11 ms·
I haven't found it in the code yet, but the landing page's protocol diagram with optional "/auth/verify" might have potential to be abused as a decryption oracl
by sweis 10y ago
I haven't found it in the code yet, but the landing page's protocol diagram with optional "/auth/verify" might have potential to be abused as a decryption oracle. It depends how they check the nonce.
- remy_ 10y agoThe authentication token follows a very specific pattern to prevent this type of attacks. For example an authentication token would look like this: gpgauthv1.3.0|36|8661be60-23df-11e5-b16c-0002a5d5c51b|gpgauthv1.3.0. Both the server and client check for the consistency of that format.
- sweis 10y agoGot it. Here's the code: https://github.com/passbolt/passbolt/blob/master/app/Controller/Component/Auth/GpgAuthenticate.php#L105 https://github.com/passbolt/passbolt/blob/master/app/Control... I didn't know gpgauth existed, but this is what they appear to be using (the site has a broken cert): https://gpgauth.org/ https://gpgauth.org/